ISO/IEC 27036
ISO/IEC 27036 is a standard in the ISO/IEC 27000 family that provides guidance on managing information security in relationships with suppliers and other third parties. It is intended to help organizations address the security risks that arise when they rely on external providers for products or services. Because no external evidence was available for this entry, the specifics of its structure, parts, and content cannot be stated with confidence and should be verified against the published standard.
ISO/IEC 27036 is a guidance standard within the ISO/IEC 27000 series addressing information security for supplier and third-party relationships. It is positioned as supporting guidance rather than a certifiable management system standard; unlike ISO/IEC 27001 (whose ISMS requirements in clauses 4 through 10 are certifiable), ISO/IEC 27036 provides recommendations and would typically be applied to inform an organization's supplier-related risk treatment and controls. Practitioners should note that the precise scope, number of parts, and detailed content of ISO/IEC 27036 depend on the specific edition and cannot be asserted here, as no supporting evidence was provided; consult the current published version and relevant accredited sources before relying on any specific claim.
Why it matters
Most organizations depend on external suppliers, service providers, and other third parties for critical products and services, and each of those relationships can introduce information security risk that falls outside the organization's direct control. ISO/IEC 27036 matters because it provides structured guidance for addressing precisely this category of risk, helping organizations think systematically about how security expectations are set, communicated, and maintained across supplier relationships rather than leaving them to ad hoc arrangements.
For compliance and GRC teams, supplier security is a recurring theme across frameworks. In an ISO/IEC 27001 program, supplier-related risks are treated through the ISMS risk assessment and the selection of applicable controls via the Statement of Applicability, and guidance-oriented standards such as ISO/IEC 27036 can inform how those supplier controls are designed and applied. In a SOC 2 examination, third-party and vendor management considerations may be relevant depending on the scope and the Trust Services Criteria selected. Because ISO/IEC 27036 is guidance rather than a certifiable management system standard, it does not itself produce a certificate or an attestation report, and its value lies in shaping practice rather than in a formal audit outcome.
Because no external evidence was available for this entry, the specific structure, parts, and detailed content of ISO/IEC 27036 cannot be stated with confidence here. Practitioners should verify all specifics against the current published standard before relying on any particular claim about its requirements or scope.
Who it's relevant to
Inside ISO/IEC 27036
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27036.